SynthID Explained: How Google's Invisible AI Watermark Works
Four different watermarking methods share one brand name. Here is what each one actually does to your content.
SynthID is a family of invisible watermarks built by Google DeepMind and added to AI content at the moment it is generated. It is not a logo, not a badge, and not a tag attached to the file.
Google says SynthID has marked more than 100 billion images and videos plus 60,000 years of audio since it launched in 2023. That makes it the most widely deployed AI watermark in the world.
This guide covers what the signal is, how the text, image, audio and video versions differ mechanically, what the public SynthID Detector can check, what edits the mark survives, and why it is built to resist removal.
What Is SynthID?
SynthID is an invisible signal that Google's AI tools embed inside content as they create it. A person looking at the image or reading the text cannot detect anything unusual. A detector trained on the signal can measure it.
The key word is embedded. SynthID does not sit in a file header or a metadata block that a converter can drop. It lives in the content itself: in the pixel values of an image, in the waveform of audio, in the word choices of text.
That design choice is the whole point. Metadata travels beside the content and falls off easily. A signal woven into the content travels with the content, including through a re-save or a re-upload.
SynthID only covers content from tools that embed it. As of August 2026 that means Google's own generative models plus a growing set of outside adopters. Content from a model that never embedded the mark has no SynthID to find, and that absence proves nothing at all.
- Invisible: no visible logo, badge, or overlay on the content.
- Embedded at generation: added while the model produces the output, not bolted on afterward.
- Not metadata: the signal is in the pixels, samples, or tokens, not in a file field.
- Scoped: present only in output from tools that implement it.
Publishing content made with Gemini, Imagen, or ChatGPT means shipping SynthID signals you cannot see. We will map where provenance and disclosure belong in your content workflow.
Book a ConsultationHow the Four SynthID Variants Differ
SynthID is one brand covering four genuinely different techniques, one per content type. Understanding which variant applies to your content tells you how durable the mark is and how it can be checked.
For images and video, DeepMind uses a pair of deep learning models trained together: one adds the watermark to the pixels, the other reads it back. Google describes it as embedding "an invisible digital watermark" directly in the image, and for video the mark goes "into the pixels of every video frame". Both are perceptual watermarks operating on visual data.
For audio, the mark is embedded into the sound itself in Lyria music output and NotebookLM podcast audio. Google says it resists "adding noise, MP3 compression, or changing the speed of the track".
SynthID text works on an entirely different principle. There are no pixels to modify, so instead the system alters how the model picks its words.
| Variant | What carries the signal | How it is added | Where it appears |
|---|---|---|---|
| Image | Pixel values across the whole image | Encoder model applies the mark; decoder model reads it | Imagen, Gemini image output, Nano Banana |
| Video | Pixels of every individual frame | Same pixel technique, applied frame by frame | Veo and Google video generation |
| Audio | The audio waveform itself | Mark embedded in the generated sound | Lyria, NotebookLM audio overviews |
| Text | The model's choice of words | Logits processor biases token sampling | Gemini app and web output |
How Does SynthID Work for Text?
SynthID text works by nudging the model's word choices in a pattern a detector can measure later. Google's developer documentation describes it as a logits processor that "augments the model's logits using a pseudorandom g-function to encode watermarking information".
In plain terms: at every step, the model scores thousands of possible next words. Many of those scores are close together, and several words would read equally well. SynthID uses a secret keyed function to favour a particular subset of those near-tied options.
One word choice tells you nothing. Across hundreds of words, the pattern becomes measurable. A Bayesian detector scores the passage and returns watermarked, not watermarked, or uncertain.
This mechanism explains the text variant's specific weaknesses. Google states plainly that watermarking "is less effective on factual responses, as there is less opportunity to augment generation without decreasing accuracy". If you ask for a phone number or a date, the model has no near-tied alternatives to choose between, so there is nowhere to hide a signal.
It also means short output is weak output. Google says the technique "works best when a language model generates longer responses". A two-sentence answer may not carry enough word choices to score confidently.
- The watermark is a bias in ordinary word selection, not hidden characters or spacing tricks.
- Detection is statistical and returns a confidence state, not a yes or no fact.
- Low-entropy output such as facts, code, or lists carries a weaker signal.
- Short passages may fall below the length needed for a confident read.
What the SynthID Detector Portal Actually Does
The SynthID Detector is a Google-run web portal where you upload a file and it reports whether a SynthID watermark is present. Google's announcement describes it as scanning "the media for a SynthID watermark" in an "image, audio track, video or piece of text created using Google's AI tools".
It does more than return a yes or no. For images the portal "indicates areas where a watermark is most likely", and for audio it "pinpoints specific segments where a SynthID watermark is detected". That per-region reporting matters when only part of a file was AI-generated.
Access is the catch. The portal is not a public SynthID checker anyone can open. Google says "journalists, media professionals and researchers can join our waitlist to gain access", and it is running the rollout with early testers rather than opening it to everyone.
Consumers get a lighter path instead. SynthID verification is built into the Gemini app, where you can upload an image and ask whether Google AI made it. Google reported 50 million uses of that feature by May 2026 and said verification is expanding into Search and Chrome.
One limit applies to every route. The detector reads SynthID, and only SynthID. It is not a general AI detector, and it cannot judge content from a model that never embedded the mark. Our AI watermark detector guide covers what the wider detection tooling can and cannot do.
- Accepts: images, audio, video, and text, with rollout staged by type.
- Reports: presence plus the regions or segments most likely marked.
- Access: waitlist for journalists, media professionals, and researchers.
- Consumer route: SynthID verification inside the Gemini app, plus Search and Chrome.
- Cannot do: identify AI content that carries no SynthID signal.
What SynthID Survives, and Where It Breaks Down
SynthID survives ordinary editing and sharing, and degrades under heavy or stacked transformation. Google's published claims are specific and worth reading literally rather than generously.
For images and video, Google says the mark is "designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression". For audio it says the mark "can't be altered by common modifications like adding noise, MP3 compression, or changing the speed".
Screenshots are the question people ask most, and the answer follows from where the signal lives. The image mark is in the pixels, so a screenshot copies the pixels and generally carries the mark with them. Google does not list screenshots among its named survivable edits, so treat a screenshot as likely to preserve the signal rather than guaranteed to.
Text behaves differently again. A screenshot of AI text turns words into an image, which removes the text signal from that file, though the words themselves still carry it if anyone transcribes them back.
DeepMind's own SynthID-Image research paper tested 30 transformations across six categories and found detection held up well on individual edits and fell off most when several transformations were stacked together. It also flagged awkward content types: black-and-white images, logos with very few uniform colours, and images with slow gradients give the watermark less room to hide.
Google has never claimed the mark is unbreakable. Its own wording is that SynthID "isn't foolproof against extreme image manipulations". Our own reading of the rest is that SynthID is not a general answer to identifying AI-generated content either: it reports on a signal Google's tools embedded, so it says nothing at all about output from a model that never embedded one.
- Survives (images and video): cropping, filters, colour changes, frame-rate changes, lossy compression.
- Survives (audio): added noise, MP3 compression, speed changes.
- Survives (text): copy and paste, light editing, moving between documents.
- Degrades: stacked transformations, extreme manipulation, very low-detail or flat-colour images.
- Degrades badly (text): thorough rewriting, translation to another language, very short output, factual answers.
- Does not apply: any content from a tool that never embedded SynthID.
SynthID vs C2PA: Two Halves of One Problem
SynthID and C2PA solve different halves of content provenance, which is why the major AI companies now ship both. SynthID answers whether a signal is present in the content. C2PA answers what happened to the file and who vouches for it.
C2PA Content Credentials are cryptographically signed metadata attached to a file, recording origin and edit history. That structure carries far more detail than a watermark can: which tool, which version, which edits, signed by whom. Our C2PA content provenance guide covers the standard in full.
The tradeoff is durability. OpenAI's own developer documentation states that "editing, converting, or sharing a file can remove its metadata", while "a SynthID watermark is part of the image or audio itself and may survive some transformations".
Stacking them covers each other's gaps. Google sits on the C2PA steering committee and now ships Content Credentials in Pixel Camera and Google Photos alongside SynthID in its generative models. OpenAI joined the same steering committee in May 2026 and began embedding SynthID in generated images and audio.
For a broader view of who marks what across every major vendor, see which AI models watermark their output, and our pillar on AI watermarking for how the category works overall.
| Dimension | SynthID | C2PA Content Credentials |
|---|---|---|
| What it is | Signal embedded in the content | Signed metadata attached to the file |
| Information carried | Presence of a mark, and roughly where | Full origin and edit history, signed |
| Survives re-save or format conversion | Often yes | Usually no |
| Survives screenshot | Image and audio marks usually do | No |
| Who can verify | Holders of the matching detector | Any C2PA-aware viewer |
| Open standard | No, Google-controlled except for text | Yes, published open specification |
Which Tools Embed SynthID
Google embeds SynthID by default across its generative models, and adoption now reaches beyond Google. On the Google side, that covers Gemini image output, Imagen, Veo video, Nano Banana, Lyria music, and NotebookLM audio overviews.
The most consequential outside adopter is OpenAI. In May 2026 it joined the C2PA steering committee and began adding SynthID watermarks to generated images, later extending the same treatment to supported audio and shipping a public verification tool at openai.com/verify.
One recent change is worth understanding, because it is routinely misread. In August 2026 Google added a Media Watermark toggle in Gemini settings that lets users turn off the visible watermark on their AI creations. Reporting on the change confirmed the invisible SynthID signal and C2PA data stay in the file either way.
That distinction trips up a lot of people. Turning off a visible badge is a display setting. The embedded signal is applied at generation and is not exposed as a user control. Our Gemini watermark guide walks through what that toggle does and does not change.
- Google: Gemini, Imagen, Veo, Nano Banana, Lyria, NotebookLM audio.
- OpenAI: SynthID in supported generated images and audio since May 2026.
- Not covered: models from vendors that have not adopted it.
- Visible vs invisible: the Gemini visible-watermark toggle does not remove SynthID.
Is SynthID Open Source?
Partly. One of the four variants is open source, and the other three are not. Getting this right matters, because "SynthID is open source" gets repeated far more broadly than the facts support.
DeepMind released SynthID Text in October 2024 alongside a paper in Nature. The reference implementation lives in the google-deepmind/synthid-text repository under Apache 2.0 for code and CC-BY for other materials, and a production version ships inside Hugging Face Transformers from version 4.46.0.
That release includes both sides: the watermarking logits processor and the detectors, including the Bayesian detector and its training code. Any developer can add SynthID-style watermarking to their own language model.
The image, video and audio watermarks are not open source. Their encoder and decoder models stay with Google, which is why verification of those types runs through Google's own detector and partner integrations rather than a tool you can self-host.
There is a design reason for the split, not just a commercial one. A text watermark is keyed, so publishing the method does not publish anyone's key. A perceptual image watermark is harder to protect once the decoder is public, since an attacker with the decoder can test edits until the signal disappears.
Why SynthID Is Built to Resist Removal
SynthID is designed so that removing it is a structural problem, not a procedural one. This page explains why removal is hard, and it does not provide removal or SynthID bypass steps.
Every watermark remover tool sold today targets a visible overlay: a logo, a stock-photo grid, a corner badge. Those tools work on pixels a human can point at. SynthID gives them nothing to point at, because the signal is spread across the whole image rather than sitting in one region.
Stripping metadata does nothing either. Converting a file, screenshotting it, or running an EXIF cleaner removes C2PA credentials and leaves the SynthID signal in place. That asymmetry is the reason both signals are shipped together.
The practical route to destroying the mark is to destroy enough of the content to carry it. Heavy recompression, aggressive regeneration, or thorough rewriting can push a detector toward uncertain, and Google says as much for text. What that costs you is the content: the passage is no longer what the model wrote, and the image is no longer the image you generated.
There is also a governance dimension. SynthID is one of the mechanisms vendors point to when demonstrating machine-readable marking of synthetic output. Deliberately defeating a transparency signal on content you then present as human-made is a policy and disclosure problem before it is a technical one, and our guide on whether removing an AI watermark is legal covers where the lines sit.
- Not a region: the signal is distributed, so overlay-removal tools have no target.
- Not metadata: EXIF strippers and format conversions leave SynthID intact.
- Degradation, not deletion: heavy transformation lowers detector confidence and damages the content.
- Legitimate cases exist: removing a visible badge from your own output is a display choice, not a provenance strip.
Frequently Asked Questions
- SynthID text works by biasing which words a model picks while it writes. Google describes it as a logits processor that augments the model's scores using a pseudorandom g-function, favouring one subset of the near-tied word options at each step. Over a long enough passage, that bias becomes a measurable pattern, and a Bayesian detector scores the text as watermarked, not watermarked, or uncertain.
- For images it usually does, because the SynthID image watermark lives in the pixels and a screenshot copies those pixels. Google does not list screenshots among its named survivable edits, so treat it as likely rather than guaranteed. C2PA metadata does not survive a screenshot at all. A screenshot of AI-generated text removes the text signal from that file, since the words become an image.
- Only the text version. DeepMind released SynthID Text in October 2024 with a Nature paper, publishing the watermarking and detection code under Apache 2.0, with a production implementation in Hugging Face Transformers 4.46.0 and later. The image, video, and audio watermarks are not open source, and their encoder and decoder models remain with Google.
- Accuracy depends on the content type and how much the content was altered, and Google has not published a single headline accuracy figure for the shipping detector. Its own material states that SynthID is not foolproof against extreme image manipulations, and the signal only speaks to content from tools that embedded it in the first place. DeepMind's SynthID-Image research found detection held up across individual transformations and weakened most when several were stacked together.
- They solve different halves of provenance. SynthID embeds a signal inside the content, so it survives re-saving and format changes but carries almost no detail. C2PA attaches signed metadata to the file, carrying full origin and edit history that a converter or screenshot can strip. Google and OpenAI now ship both together so each covers the other's weakness.
- Yes, for images and supported audio. OpenAI announced in May 2026 that it had joined the C2PA steering committee and begun embedding SynthID watermarks in generated images, later extending it to supported audio, alongside a public verification tool. Check OpenAI's provenance documentation for the current list of covered surfaces, since coverage has been expanding.
- No. SynthID is designed to be imperceptible to people and readable only by a matching detector. It is separate from the visible badge some AI tools burn into an image corner. In August 2026 Google added a setting in Gemini that lets users turn off that visible mark, and the invisible SynthID signal stays embedded either way.
- Not one that is open to everyone. The SynthID Detector portal is limited to a waitlist for journalists, media professionals, and researchers. The consumer route is SynthID verification inside the Gemini app, where you can upload an image and ask whether Google AI generated it, with Google expanding verification into Search and Chrome. Third-party sites advertising a SynthID checker are not running Google's detector.
- It is designed to resist removal, and this page does not describe methods for stripping it. The signal is spread across the whole image or the whole passage rather than sitting in one place, so watermark-remover tools built for visible overlays have nothing to target, and metadata strippers leave it untouched. Heavy transformation can lower a detector's confidence, but it damages the content in the process.
Need a provenance policy for the AI content your team ships?
Book a free 30-minute AI workflow audit with Layer3 Labs. We will map where SynthID, C2PA, and disclosure fit into how your team generates, edits, and publishes content.
Book Your Free AI Workflow Audit